upvote
reply
And the discussion here, with 215 comments: https://news.ycombinator.com/item?id=48467705
reply
deleted
reply
Is it possible to fix it in a backwards compatible way? Removing lifecycle scripts is at least a semver major change, and would complicate existing projects relying on packages with lifecycle scripts from upgrading.
reply
This is a real world trolley problem scenario. You can break workflows or you can let everyone get pwned by supply chain attacks. Which is the greater harm?
reply
People will not adopt a safer version if it broke their workflows. Adoption is part of preventing supply chain attacks.
reply
They will if it's the only version. Eventually.
reply
deleted
reply